First published: Mon Aug 12 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Spectra allows Stored XSS.This issue affects Spectra: from n/a through 2.14.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sectona Spectra | <=2.14.1 | |
Brainstorm Force WordPress Spectra | <=2.14.1 | |
Sectona Spectra | <=2.14.1 |
Update to 2.15.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7590 is categorized as a high-severity vulnerability due to its potential for Stored XSS attacks.
To mitigate CVE-2024-7590, update Brainstorm Force Spectra to version 2.14.2 or later.
CVE-2024-7590 affects Brainstorm Force Spectra versions up to and including 2.14.1.
Stored XSS allows an attacker to inject malicious scripts that are stored on the server and executed in the browser of users visiting the page.
Users of Brainstorm Force Spectra versions up to 2.14.1 on their sites are at risk due to CVE-2024-7590.